apple-appstore-reviewer

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is intended for static analysis of project configuration files (e.g., Info.plist, entitlements, and privacy manifests). Accessing these files is necessary for the stated purpose of identifying App Store compliance issues and does not involve harvesting sensitive user credentials or system secrets.\n- [SAFE]: The skill does not contain any instructions for network operations, external downloads, or command execution. It explicitly restricts the agent to reviewing code and producing reports without making initial code modifications.\n- [SAFE]: The skill involves an indirect prompt injection surface as it processes untrusted codebase data. Ingestion points: iOS project files such as Info.plist, StoreKit code, and entitlements in the target repository. Boundary markers: Absent. Capability inventory: Analysis is limited to generating a Markdown report; no subprocesses, network requests, or dynamic code execution are performed. Sanitization: Absent. The risk is considered negligible due to the lack of exploitable capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 07:28 AM
Security Audit — agent-trust-hub — apple-appstore-reviewer